oki,tak ja som teraz ako 1. spravil ten combo fix tu je vysledok:(ten mcofing som este nesptavil (nvm ci je to podstatne)
ComboFix 10-03-01.01 - Uživateľ . 03. 2010 20:54:48.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.511.252 [GMT 1:00]
Spuštěný z: c:\documents and settings\Uživateľ\Plocha\abraka.com.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Rezidentní štít AV je zapnutý
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\UIVATE~1\LOCALS~1\Temp\cvasds0.dll
c:\windows\system32\vbzlib1.dll
.
((((((((((((((((((((((((( Soubory vytvořené od 2010-02-01 do 2010-03-01 )))))))))))))))))))))))))))))))
.
2010-02-28 18:31 . 2010-02-28 18:32 -------- d-----w- c:\program files\trend micro
2010-02-28 18:31 . 2010-02-28 18:32 -------- d-----w- C:\rsit
2010-02-22 10:51 . 2010-02-22 10:51 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-02 15:55 . 2010-01-02 15:55 -------- d-----w- c:\program files\Ask.com
2010-01-02 15:54 . 2010-01-02 15:54 -------- d-----w- c:\program files\DsNET Corp
2009-12-13 08:48 . 2004-08-18 12:00 78716 ----a-w- c:\windows\system32\perfc005.dat
2009-12-13 08:48 . 2004-08-18 12:00 431654 ----a-w- c:\windows\system32\perfh005.dat
2009-10-19 12:07 . 2009-10-19 12:07 2080 ----a-w- c:\program files\Uninstall.ini
2009-10-19 12:07 . 2009-01-07 18:24 74330 ----a-w- c:\program files\Uninstall.exe
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE90C38C-97CF-4696-B290-C7973DC9675E}]
2009-10-02 15:09 815104 ----a-w- c:\program files\Little Fighter 2 Toolbar\v3.3.0.2\Little_Fighter_2_Toolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-11-18 17:40 1196936 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{C3CD744D-2FAE-4640-8297-16B5DA423104}"= "c:\program files\Little Fighter 2 Toolbar\v3.3.0.2\Little_Fighter_2_Toolbar.dll" [2009-10-02 815104]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]
[HKEY_CLASSES_ROOT\clsid\{c3cd744d-2fae-4640-8297-16b5da423104}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{C3CD744D-2FAE-4640-8297-16B5DA423104}"= "c:\program files\Little Fighter 2 Toolbar\v3.3.0.2\Little_Fighter_2_Toolbar.dll" [2009-10-02 815104]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-11-18 1196936]
[HKEY_CLASSES_ROOT\clsid\{c3cd744d-2fae-4640-8297-16b5da423104}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-10-23 202024]
"SmartRAM"="c:\program files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe" [2009-01-06 202064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-10-07 1461080]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\U§ivate–\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Metin2"=C:\Metin2.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"d:\\Medium games\\NTSD1.9\\NTSD_beta1.9\\NTSD beta1.9.exe"=
"d:\\Medium games\\little fighter mega\\lf2.net.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"d:\\SUPER GAMES\\Microsoft Games\\age of empires II\\empires2.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"d:\\SUPER GAMES\\worms 4 mayhem\\WORMS 4 MAYHEM.EXE"=
"d:\\downloads\\metin2cz\\metin2.bin"=
"d:\\Medium games\\LF2_v2.0a\\lf2.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [21. 12. 2007 8:21 35168]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [7. 10. 2009 9:16 472280]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [5. 3. 2009 8:31 246520]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6. 3. 2009 8:58 685816]
S3 DMZGBMZ;DMZGBMZ;c:\docume~1\UIVATE~1\LOCALS~1\Temp\DMZGBMZ.exe --> c:\docume~1\UIVATE~1\LOCALS~1\Temp\DMZGBMZ.exe [?]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [22. 2. 2010 11:51 23456]
S3 LQR;LQR;c:\docume~1\UIVATE~1\LOCALS~1\Temp\LQR.exe --> c:\docume~1\UIVATE~1\LOCALS~1\Temp\LQR.exe [?]
S3 MJIGUZLUNR;MJIGUZLUNR;c:\docume~1\UIVATE~1\LOCALS~1\Temp\MJIGUZLUNR.exe --> c:\docume~1\UIVATE~1\LOCALS~1\Temp\MJIGUZLUNR.exe [?]
S3 OWGEISPDFJRLG;OWGEISPDFJRLG;c:\docume~1\UIVATE~1\LOCALS~1\Temp\OWGEISPDFJRLG.exe --> c:\docume~1\UIVATE~1\LOCALS~1\Temp\OWGEISPDFJRLG.exe [?]
S3 VIZTCOUNATRZ;VIZTCOUNATRZ;c:\docume~1\UIVATE~1\LOCALS~1\Temp\VIZTCOUNATRZ.exe --> c:\docume~1\UIVATE~1\LOCALS~1\Temp\VIZTCOUNATRZ.exe [?]
S3 XNPLKQRDP;XNPLKQRDP;c:\docume~1\UIVATE~1\LOCALS~1\Temp\XNPLKQRDP.exe --> c:\docume~1\UIVATE~1\LOCALS~1\Temp\XNPLKQRDP.exe [?]
S3 ZXP;ZXP;c:\docume~1\UIVATE~1\LOCALS~1\Temp\ZXP.exe --> c:\docume~1\UIVATE~1\LOCALS~1\Temp\ZXP.exe [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Obsah adresáře 'Naplánované úlohy'
2010-03-01 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 19:36]
2010-02-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
2010-03-01 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-11-18 17:40]
2010-03-01 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-02 20:18]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://eu.ask.com?o=15383&l=dis
IE: E&xportovať do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Uživateľ\Data aplikací\Mozilla\Firefox\Profiles\eirr5rkz.default\
FF - prefs.js: browser.search.selectedEngine - ICQ Search
FF - prefs.js: browser.startup.homepage - hxxp://
www.warxtreme.com/index.php
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ATU3&o=15380&locale=en_EU&q=
---- NASTAVENÍ FIREFOXU ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-01 20:59
Windows 5.1.2600 Service Pack 3 NTFS
skenování skrytých procesů ...
skenování skrytých položek 'Po spuštění' ...
skenování skrytých souborů ...
sken byl úspešně dokončen
skryté soubory: 0
**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------
- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\Ati2evxx.dll
.
Celkový čas: 2010-03-01 21:01:32
ComboFix-quarantined-files.txt 2010-03-01 20:01
Před spuštěním: 1 039 527 936
Po spuštění: 1 011 503 104
WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /bootlog
- - End Of File - - 92FCD79D3D9FD5454FB31BDB21B5CC0A
DAL SEM TEN SAFE BOOT A DAL K TOMU NETWORK A TED MAM ONLY NUDZOVY REZIM S NETOM ,mg TERAZ TO MM ZMENIT NA KTORE?